Privacy Policy

How Pharmacy HQ collects, uses, and protects your information.

Last updated: 24 August 2026  ·  Effective: 7 September 2026

In plain English: We collect the minimum data needed to run your pharmacy operations dashboard. We don't sell your data, we don't share it with advertisers, and your operational data belongs to you. This policy explains the details.

Contents

  1. Who we are
  2. What information we collect
  3. How we use your information
  4. Who we share information with
  5. AI features and Anthropic
  6. PreCheck, Webster pack AI verification
  7. Data storage and security
  8. How long we keep your data
  9. Your privacy rights (Australian Privacy Act)
  10. Cookies and tracking
  11. Pharmacy and health-adjacent data
  12. Our mobile apps
  13. Children's privacy
  14. Changes to this policy
  15. Contact us

1. Who we are

Pharmacy HQ is a software-as-a-service (SaaS) product providing staff operations dashboards for Australian pharmacies. It is operated by Pharmacy HQ Pty Ltd (ACN 698 203 164 · ABN 86 698 203 164), an Australian company with registered office at C/- Perrier Ryan Business Advisors, Level 1, 30 Lisburn Street, East Brisbane QLD 4169.

In this policy, "Pharmacy HQ", "we", "us" and "our" refer to Pharmacy HQ Pty Ltd. "You" refers to the pharmacy owner, manager, or staff member using our service.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. What information we collect

Account information

When you create a Pharmacy HQ account, we collect:

Operational data you enter

All data entered by you or your staff into the application is stored under your pharmacy's account and includes:

Important: Pharmacy HQ stores both operational data (staff records, tasks, diary entries) AND, when you enable the relevant features, patient-adjacent operational data (Webster patient profiles including Medicare/DVA/NDIS, Care Transfer records, Staged Supply dispensing events, vaccination claim records). All such data is stored under your pharmacy's account with strict access controls. We are not a regulated health records platform; the dispensing system at your pharmacy remains the system of record for full clinical medication history. See Section 9 below for the full list of patient-adjacent data categories.

Sensitive information (APP 3.3). Where the pharmacy chooses to record a patient's Aboriginal and/or Torres Strait Islander identification (used to confirm IDAA, Indigenous Dose Administration Aid, program eligibility), that information is "sensitive information" under the Australian Privacy Principles. The pharmacy is the APP entity collecting it; Pharmacy HQ acts as the data processor on the pharmacy's behalf. Pharmacies must obtain the patient's consent before recording this field and may only use it for the specific purpose of confirming IDAA program eligibility. Pharmacy HQ enforces this by gating the field behind an explicit consent prompt at the Webster enrolment form. Concession status and living-setting metadata are not classified as sensitive information under the APPs but are still treated with the same access controls as other patient-adjacent data.

Technical data collected automatically

When you use our application, we or our infrastructure providers may automatically collect:

Data typeCollected byPurpose
Auth tokens & session dataFirebase Authentication (Google)Keeping you signed in securely
Realtime database (all app data)Firebase Realtime Database (Google)Live sync across devices
Payment & billing dataStripe, Inc.Processing subscription payments
Email delivery logsResend, Inc.Welcome, trial, billing, and claim-nag emails

3. How we use your information

We use the information we collect for the following purposes:

We will never sell your data to third parties, use it to serve you advertisements, or share it with anyone who is not listed in Section 4 of this policy.

4. Who we share information with

We share data only with the following trusted third-party providers, and only to the extent necessary to provide the service:

ProviderCountryPurposeTheir Privacy Policy
Google Firebase USA (data may be stored in Australia/APAC data centres, subject to Google's data residency settings) Authentication, real-time database, cloud functions firebase.google.com/support/privacy
Stripe, Inc. USA Payment processing and subscription management stripe.com/au/privacy
Resend, Inc. USA (Tokyo region) Transactional email delivery (welcome, password reset, billing alerts, trial expiry warnings, claim-nag reminders) resend.com/legal/privacy-policy
Cloudflare, Inc. USA (global edge) DNS hosting, Email Routing (inbound automated reports e.g. fridge temperature logs), Workers (transforming inbound emails into structured records), and Turnstile, the bot check on a pharmacy's public online-booking page. Turnstile sees the visitor's IP address and browser characteristics to decide whether the request looks automated; it does not receive anything typed into the booking form. cloudflare.com/privacypolicy
Anthropic PBC USA AI assistant (Claude API), powers Help Chat, Policy Chat, Workflow Chat, Pre-Check Webster pack image-analysis. Anthropic does not store or train on prompts under their commercial terms. anthropic.com/legal/privacy
Twilio Inc. USA (global) Outbound + inbound SMS (delivery + collection notifications, holiday-hours cohort SMS, sick-call cascades, pre-shift reminders) twilio.com/en-us/legal/privacy
Pharmacy Programs Administrator (PPA) , per-claim Australia When you submit a MedsCheck, NIPVIP, CVCP, DAA, or Staged Supply claim, patient identifiers (name, DOB, Medicare/DVA), vaccine batch/lot, and service particulars are sent to PPA's API under your existing Service Provider Agreement ppaonline.com.au/privacy
Xero , when connected New Zealand If you connect Xero in Pharmacy Settings → Integrations → Xero Payroll, approved timesheet data + staff identity is pushed to Xero on demand. Pharmacy HQ does not pull data from Xero. xero.com/au/legal/privacy
Google Maps Platform , when enabled USA (global) If you enable Deliveries route optimisation, delivery addresses are geocoded + routed via Google Maps APIs. Address strings only, no patient names. policies.google.com/privacy

Authoritative sub-processor list: for the current authoritative list of every data sub-processor + their role + jurisdiction, see pharmacyhq.com.au/sub-processors. That page is updated whenever a sub-processor is added, removed, or changes role, it is the single source of truth and takes precedence over any listing in this document.

All of these providers are bound by contracts that require them to handle your data securely and only for the specified purpose. Data transfers to the USA are covered by standard contractual clauses.

We may also disclose your information if required to do so by Australian law (for example, in response to a court order or regulatory request).

4a. AI features and Anthropic

Pharmacy HQ provides four AI-powered surfaces, all backed by Anthropic's Claude model:

Not everything below is switched on yet. PreCheck, the MedsCheck AI scribe, and AI reading of emailed scripts are still in testing and are not enabled for live pharmacies. Each is switched on only after that testing completes, and this section applies to each from the moment it is enabled.

What is sent to Anthropic

For Help / Policy / Workflow chats, the text of your question and the contextual data the assistant needs to answer (which may include patient names, prescription details, or operational records) is transmitted to Anthropic's API in the United States. For PreCheck, the data residency and identifier-stripping controls described in Section 4b apply.

What Anthropic does with it

Under Anthropic's commercial terms in effect at the date of this policy, requests and responses are not used for model training and are not retained beyond the time required to deliver the response (subject to Anthropic's standard logging for abuse prevention).

What we log on our side

We log metadata only, timestamp, surface (help / policy / workflow / pre-check), tokens consumed, latency. We do not log the prompt or the response text on our side. This is a deliberate PHI-hygiene choice; the trade-off is we can't audit the content of historical AI queries.

How to opt out

The pharmacy owner can disable AI features for the entire pharmacy in Pharmacy settings → AI features. Once disabled, no Anthropic API calls occur from your pharmacy's account: every AI surface, the Help, Policy and Workflow chats, the MedsCheck AI scribe, invoice reading, incident auto-tagging, the QSPP writing tools, and PreCheck, refuses instead of calling out. The switch is enforced on our servers, not in the browser, so it holds regardless of which device or app version a staff member is using. Only the owner can change it; a manager cannot. Prescriptions emailed to your script inbox continue to arrive while AI is off, they are simply filed without the patient and prescriber details being read out of them. PreCheck is additionally opt-in per patient (Section 4b): patient consent and this pharmacy-level switch must both allow it.

4b. PreCheck, Webster pack AI verification

PreCheck is an assistive workflow tool that captures an end-of-pack photograph of a Webster (dose administration aid) pack and runs AI image analysis to count pills per cell + flag potential discrepancies. The pharmacist reviews every result and is solely responsible for verifying the pack before it leaves the pharmacy. PreCheck is not a medical device and does not constitute a clinical determination.

Patient consent (per patient, opt-in)

PreCheck is gated on per-patient consent. The pharmacist obtains the patient's documented consent at Webster enrolment and records it on the patient's Webster profile inside Pharmacy HQ (a structured field: granted, at, by, with a withdrawal field if consent is later revoked). PreCheck capture refuses to upload a photo for a patient whose consent is not granted. Consent is patient-level (not pharmacy-level) and is withdrawable at any time via Pharmacy Settings or by request to the pharmacy.

What is sent, and what is NOT sent

What we send to the AI provider: the cropped image of the pack grid only (the rectangle inside the violet outline shown on the camera preview), plus the expected pill counts per slot as a JSON array. The image is cropped client-side using a fixed bounding rectangle before it is uploaded to our servers; everything outside the violet outline is discarded before the image data exists.

What we do NOT send: the patient's name, date of birth, Medicare number, AHPRA number, or any other personal identifier. There is no patient ID, no store ID, and no timestamp in the AI payload that could correlate the image with a patient. We additionally run a server-side OCR redaction check on the cropped image (Google Cloud Vision textDetection) before any AI call; if the OCR detects identifier-shaped text (patient name, DOB pattern, Medicare pattern, or AHPRA pattern) we BLOCK the AI call and prompt the pharmacy staff member to reframe and re-capture.

Where the AI runs

The PreCheck AI call goes to Google Cloud Vertex AI in the australia-southeast1 (Sydney) region, hosting Anthropic's Claude model. This is the same Sydney Google Cloud project where the rest of your pharmacy data is stored, your patient data does not leave Australia for the PreCheck pipeline.

Retention

Vertex AI publisher logging is disabled on the PreCheck call (header: X-Vertex-AI-Logging-Off: true), and under Anthropic's Vertex policy in effect at the date of this policy, requests and responses are not used for model training and are not retained beyond the time required to deliver the response.

Pharmacy HQ retains the cropped photograph in your pharmacy's storage bucket alongside the AI result for the audit trail. Photographs are deleted in line with our standard retention schedule (Section 6) or earlier on request.

Audit trail and pharmacy attestation

Every PreCheck capture records a structured privacy field, consent state at capture time, crop bounds applied, OCR preflight result, AI provider, AI region, and retention policy. Pharmacy owners can generate a Privacy Audit Pack (PDF) from the PreCheck tab covering the last 30 days of activity, suitable for OAIC, AHPRA, or insurer enquiries.

How to opt out

Individual patients can withdraw consent at any time by asking their pharmacy to un-tick the PreCheck consent on their Webster profile; subsequent captures for that patient are blocked. Pharmacies can disable PreCheck for the entire store in Pharmacy Settings → PreCheck.

Privacy Impact Assessment

The full Privacy Impact Assessment for PreCheck, covering personal information flows, the risk register, mitigations, and the Australian Privacy Principles compliance map, is published at /pharmacyhq-fixes/precheck-pia.html. It is updated when PreCheck Phase 2 (AI go-live) ships and at each new pharmacy onboarding.

5. Data storage and security

Your data is stored in Firebase Realtime Database, hosted by Google. All data is protected by:

Edge security and inbound mail processing. DNS for pharmacyhq.com.au is hosted on Cloudflare; inbound automated emails (e.g. fridge temperature logs from Clever Logger) are routed through Cloudflare Email Routing and processed by a Cloudflare Worker before being forwarded to our Cloud Functions for ingestion. Cloudflare may temporarily process the email contents in transit; we do not retain Cloudflare's processing logs beyond what their standard logging provides.

While we take reasonable technical measures to protect your data, no internet transmission or electronic storage method is 100% secure. If you become aware of any security vulnerability, please contact us immediately at security@pharmacyhq.com.au.

6. How long we keep your data

You can request earlier deletion of your data at any time by contacting privacy@pharmacyhq.com.au. Billing records may be retained longer if required by law.

7. Your privacy rights (Australian Privacy Act)

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the following rights:

Right to access your data

You can request a copy of the personal information we hold about you. We will provide this within 30 days of your request. Your operational data is accessible directly through the application at any time.

Right to correction

If any information we hold about you is inaccurate or out of date, you can correct it yourself within the application or ask us to correct it.

Right to deletion

You can request that we delete your account and associated data. Some data may be retained where required by law (e.g. financial records).

Right to complain

If you believe we have handled your personal information in breach of the Privacy Act, you can lodge a complaint with us at privacy@pharmacyhq.com.au. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

To exercise any of these rights, email privacy@pharmacyhq.com.au. We will respond within 30 days and may need to verify your identity before acting on your request.

8. Cookies and tracking

Pharmacy HQ is a single-page web application. We use the following minimal cookies and local storage:

We do not use advertising cookies, third-party tracking pixels, or social media widgets. The landing page (pharmacyhq.com.au) does not use Google Analytics or any equivalent analytics service that tracks individuals across sites.

9. Pharmacy and health-adjacent data

Pharmacy HQ is primarily a workflow and operations dashboard. We are not a clinical management system, regulated health records platform, or dispensing software. However, several features that you (the pharmacy) can optionally enable do require us to store patient-adjacent operational data.

What we may store, when your pharmacy uses the relevant feature:

What we still do not store:

All patient-adjacent data is gated by Firebase Security Rules so that one pharmacy cannot read another pharmacy's records. Per-feature sensitivity controls (e.g. the Staged Supply path is admin-SDK-write-only, every write goes through an authenticated Cloud Function with an audit log) give an extra layer for the most sensitive paths.

Pharmacy owners remain responsible for ensuring their use of the application complies with applicable pharmacy board and privacy regulations. We provide the platform; you remain the data controller for patient information under the Privacy Act.

If you have specific compliance questions for your pharmacy, we recommend seeking independent legal advice or contacting the Pharmacy Guild of Australia.

9a. Our mobile apps

We publish two iOS and Android apps. They are separate apps for separate audiences, and they collect different things. Everything in the rest of this policy applies to both; this section covers what is specific to a phone.

PHQ Team, the staff app

PHQ Team is for people who work at a pharmacy that uses Pharmacy HQ. You sign in with an account your pharmacy gives you; you cannot create one yourself. In addition to the account and operational data described in section 2, the app may collect:

Pharmacy HQ, the patient app

The patient app is for customers of a pharmacy that uses Pharmacy HQ. Alongside your account details it may hold your prescription and medication information, your Individual Healthcare Identifier, the pharmacy you are linked to, a record of the device you signed in on, and a push notification token.

Payments for physical goods are handled by Stripe. We never see or store your full card number.

Face ID, Touch ID and your PIN

Both apps can lock behind a biometric check or a PIN. Biometric data never leaves your device and is never sent to us, the device tells the app only whether the check passed.

Notifications do not contain health information

Notification text is deliberately written so that nothing sensitive appears on a lock screen. A notification will tell you that something is ready or that you have a message; it will not name a medicine or a health condition.

Permissions we ask for

PermissionAppWhy we ask
CameraBothDelivery proof photos (staff); scanning a prescription token (patient)
LocationPHQ TeamConfirming you are at the pharmacy when you clock in or out
NotificationsBothShift, message and order updates
Face ID / Touch IDBothUnlocking the app without typing a password

Every one of these is optional. You can refuse or later withdraw any of them in your device settings, and the app keeps working with that feature turned off.

Deleting your account from the apps

You can delete your account from inside either app, without contacting us.

In both apps, open Settings (the gear at the top of the screen) and choose “Delete my account”. In PHQ Team, this removes your sign-in, your membership of every pharmacy you belong to in the app, the link between your sign-in and your staff card, and your notification tokens. It does not delete your pharmacy’s employee records of you (rosters, hours, leave and pay), which Australian workplace law requires the pharmacy to keep for seven years; those belong to the pharmacy, not to your app account. A pharmacy owner’s sign-in is the pharmacy’s own account, so it is closed from the web app (Manage Team → Leave pharmacy) rather than from a phone.

In the patient app, it removes your sign-in, the link between your account and the pharmacy’s record of you, your stored consent, the record of your device, and your notification tokens. After it completes, no login can reach that record.

It does not delete your pharmacy’s own records of your prescriptions or your conversations with them. Those are the pharmacy’s health and business records, and Australian law requires the pharmacy to keep them for a set period. That is the pharmacy’s data, not your app account’s, and section 6 explains how long it is kept.

What the apps do not do

10. Children's privacy

Pharmacy HQ is a professional business tool intended for use by adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, please contact us at privacy@pharmacyhq.com.au and we will promptly delete the account.

11. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to our practices or applicable law. When we make material changes, we will:

Continued use of Pharmacy HQ after the effective date of any changes constitutes your acceptance of the updated policy.

12. Contact us

For any privacy-related questions, requests, or complaints:

We aim to respond to all privacy enquiries within 5 business days.

Office of the Australian Information Commissioner (OAIC)
If you are not satisfied with our response to a privacy complaint, you may contact the OAIC:
Website: www.oaic.gov.au  ·  Phone: 1300 363 992  ·  GPO Box 5218, Sydney NSW 2001